Buffer overflow in Qt - CVE-2018-19869

 

Buffer overflow in Qt - CVE-2018-19869

Published: May 4, 2020


Vulnerability identifier: #VU27496
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19869
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing SVG images within the qsvghandler.cpp file in Qt. A remote attacker can create a specially crafted image, pass it to he application that uses Qt library for SVG processing, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Qt
qt5-qtbase (Red Hat package)
qt5-qttools (Red Hat package)
qgnomeplatform (Red Hat package)
qt (Red Hat package)
mingw-sip
sip (Red Hat package)
mingw-qt5-qtwebkit
libqt5svg5 (Ubuntu package)
mingw-qt5-qtwebsockets
mingw-qt5-qtxmlpatterns
mingw-qt5-qt3d
mingw-qt5-qtactiveqt
mingw-qt5-qtbase
mingw-qt5-qtcharts
mingw-qt5-qtdeclarative
mingw-qt5-qtgraphicaleffects
mingw-qt5-qtimageformats
mingw-qt5-qtlocation
mingw-qt5-qtmultimedia
mingw-qt5-qtquickcontrols
mingw-qt5-qtscript
mingw-qt5-qtsensors
mingw-qt5-qtserialport
mingw-qt5-qtsvg
mingw-qt5-qttools
mingw-qt5-qttranslations
mingw-qt5-qtwinextras
mingw-python-qt5
qt5-qtxmlpatterns (Red Hat package)
qt5-qtquickcontrols (Red Hat package)
qt5-qtcanvas3d (Red Hat package)
qt5-qtconnectivity (Red Hat package)
qt5-qtdeclarative (Red Hat package)
qt5-qtdoc (Red Hat package)
qt5-qtgraphicaleffects (Red Hat package)
qt5-qtimageformats (Red Hat package)
qt5-qtlocation (Red Hat package)
qt5-qtmultimedia (Red Hat package)
qt5-qtquickcontrols2 (Red Hat package)
qt5-qtscript (Red Hat package)
qt5-qtsensors (Red Hat package)
qt5-qtserialbus (Red Hat package)
qt5-qtserialport (Red Hat package)
qt5-qtsvg (Red Hat package)
qt5-qttranslations (Red Hat package)
qt5-qtwayland (Red Hat package)
qt5-qtwebchannel (Red Hat package)
qt5-qtwebsockets (Red Hat package)
qt5-qtx11extras (Red Hat package)
qt5-qt3d (Red Hat package)
qt5 (Red Hat package)
python-qt5 (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for x86_64
SUSE Linux
Opensuse
Ubuntu
Fedora

How to mitigate CVE-2018-19869

Install updates from vendor's website.

Qt - update to 5.11.3
qt5-qtbase (Red Hat package) - update to 5.12.5-4.el8
qt5-qttools (Red Hat package) - update to 5.12.5-1.el8
qgnomeplatform (Red Hat package) - update to 0.4-3.el8
qt (Red Hat package) - update to 4.8.7-8.el7
mingw-sip - update to 4.19.13-2.fc29
sip (Red Hat package) - update to 4.19.19-1.el8
mingw-qt5-qtwebkit - update to 5.9.4-0.8.gitbd0657f.fc29
libqt5svg5 (Ubuntu package) - update to 5.9.5-0ubuntu1.1
mingw-qt5-qtwebsockets - update to 5.11.3-1.fc29
mingw-qt5-qtxmlpatterns - update to 5.11.3-1.fc29
mingw-qt5-qt3d - update to 5.11.3-1.fc29
mingw-qt5-qtactiveqt - update to 5.11.3-1.fc29
mingw-qt5-qtbase - update to 5.11.3-1.fc29
mingw-qt5-qtcharts - update to 5.11.3-1.fc29
mingw-qt5-qtdeclarative - update to 5.11.3-1.fc29
mingw-qt5-qtgraphicaleffects - update to 5.11.3-1.fc29
mingw-qt5-qtimageformats - update to 5.11.3-1.fc29
mingw-qt5-qtlocation - update to 5.11.3-1.fc29
mingw-qt5-qtmultimedia - update to 5.11.3-1.fc29
mingw-qt5-qtquickcontrols - update to 5.11.3-1.fc29
mingw-qt5-qtscript - update to 5.11.3-1.fc29
mingw-qt5-qtsensors - update to 5.11.3-1.fc29
mingw-qt5-qtserialport - update to 5.11.3-1.fc29
mingw-qt5-qtsvg - update to 5.11.3-1.fc29
mingw-qt5-qttools - update to 5.11.3-1.fc29
mingw-qt5-qttranslations - update to 5.11.3-1.fc29
mingw-qt5-qtwinextras - update to 5.11.3-1.fc29
mingw-python-qt5 - update to 5.11.3-2.fc29
qt5-qtxmlpatterns (Red Hat package) - update to 5.12.5-1.el8
qt5-qtquickcontrols (Red Hat package) - update to 5.12.5-1.el8
qt5-qtcanvas3d (Red Hat package) - update to 5.12.5-1.el8
qt5-qtconnectivity (Red Hat package) - update to 5.12.5-1.el8
qt5-qtdeclarative (Red Hat package) - update to 5.12.5-1.el8
qt5-qtdoc (Red Hat package) - update to 5.12.5-1.el8
qt5-qtgraphicaleffects (Red Hat package) - update to 5.12.5-1.el8
qt5-qtimageformats (Red Hat package) - update to 5.12.5-1.el8
qt5-qtlocation (Red Hat package) - update to 5.12.5-1.el8
qt5-qtmultimedia (Red Hat package) - update to 5.12.5-1.el8
qt5-qtquickcontrols2 (Red Hat package) - update to 5.12.5-1.el8
qt5-qtscript (Red Hat package) - update to 5.12.5-1.el8
qt5-qtsensors (Red Hat package) - update to 5.12.5-1.el8
qt5-qtserialbus (Red Hat package) - update to 5.12.5-1.el8
qt5-qtserialport (Red Hat package) - update to 5.12.5-1.el8
qt5-qtsvg (Red Hat package) - update to 5.12.5-1.el8
qt5-qttranslations (Red Hat package) - update to 5.12.5-1.el8
qt5-qtwayland (Red Hat package) - update to 5.12.5-1.el8
qt5-qtwebchannel (Red Hat package) - update to 5.12.5-1.el8
qt5-qtwebsockets (Red Hat package) - update to 5.12.5-1.el8
qt5-qtx11extras (Red Hat package) - update to 5.12.5-1.el8
qt5-qt3d (Red Hat package) - update to 5.12.5-2.el8
qt5 (Red Hat package) - update to 5.12.5-3.el8
python-qt5 (Red Hat package) - update to 5.13.1-1.el8

External References

Related Security Bulletins